A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NAvaya Control Manager
APPAvaya7.0 – 8.0.4.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiAuth Bypass
Related vulnerabilities
CVE-2025-1041CRITICAL9.9PL ✓same vendor
Zdalne wykonanie poleceń w Avaya Call Management System (CWE-20)
CVE-2024-4197CRITICAL9.9PL ✓same vendor
Unrestricted file upload umożliwiający RCE w Avaya IP Office (One-X)
CVE-2024-4196CRITICAL10.0PL ✓same vendor
RCE poprzez improper input validation w Avaya IP Office (Web Control)
CVE-2022-38168CRITICAL9.1PL ✓same vendor
Pominięcie uwierzytelnienia w Avaya Scopia Pathfinder 10/20 PTS via modyfikacja URL
CVE-2019-7001CRITICAL9.9PL ✓same vendor
SQL injection w Avaya IP Office Contact Center WebUI